Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should organisations do first to reduce common…
Cyber Security

What should organisations do first to reduce common internet safety risks across users and devices?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

Start with the basics that remove the most common exposure. Keep devices, servers, apps, IoT equipment, and browser software patched, because unpatched systems remain easy targets for compromise. Then reinforce user behaviour with simple habits such as pausing before opening links or attachments, using two factor authentication, and verifying website certificates before entering sensitive information.

Start with the highest-volume exposure points

The first move is to reduce the easy wins for attackers: patch the software people and systems rely on most, and make those updates routine rather than exceptional. That includes endpoints, servers, browsers, mobile devices, and connected equipment such as IoT devices. A good first pass is to focus on assets exposed to the internet or used every day, because they combine broad reach with a high chance of being targeted.

Organisations often try to solve internet safety with training alone, but patching is usually the faster risk reducer. When a known flaw is already public, the question is not whether it is theoretically dangerous, but whether unpatched systems are still reachable. The CIS Benchmarks are useful here because they turn patching and configuration into practical hardening baselines for common platforms.

For internet-facing systems, update cadence should be driven by exposure and business criticality, not by convenience. If an application or device cannot be patched quickly, it needs compensating controls such as segmentation, restricted access, or temporary removal from the exposed path.

Why simple user habits still matter

Once the most obvious technical exposures are being reduced, the next layer is user behaviour. The most common unsafe actions are still low-friction ones: clicking unfamiliar links, opening unexpected attachments, reusing passwords, and submitting data to untrusted sites. Basic habits, such as pausing before acting and verifying where a link goes, reduce the success rate of phishing and other social engineering attempts.

Two-factor authentication adds a useful barrier because a stolen password alone is no longer enough for many common account takeovers. It is most effective when paired with user awareness, because attackers frequently combine credential theft with fake login pages or malicious redirects. For implementation detail on authentication, session handling, and secure login flows, the OWASP Cheat Sheet Series provides practical guidance that maps well to everyday user-facing controls.

Certificate checks are a narrow but important habit for sensitive transactions. Users do not need to become protocol specialists, but they should recognise browser warnings, avoid bypassing them casually, and treat certificate problems as a signal that the connection may not be trustworthy.

Make the safe path the default across people and devices

Good internet safety is less about heroic incident response and more about removing routine exposure. That means applying updates automatically where possible, enforcing 2FA on all important accounts, and keeping browsers and operating systems current so users benefit from security fixes without having to decide each time.

Device management should support that behaviour. If people use multiple devices, the organisation needs a baseline that covers laptops, phones, tablets, and any shared or kiosk systems. The browser matters too, because it is a primary entry point for phishing, credential theft, and malicious downloads. The NCSC UK Advice and Guidance is a strong public reference for these practical controls, especially where organisations need plain-language advice that non-specialists can follow.

At scale, the main test is consistency: if one team patches quickly but another leaves old devices and browsers exposed, the organisation still has a weak entry point. The first priority is to close that unevenness before adding more advanced controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-7 — Continuous Vulnerability ManagementPatch management is central to reducing common internet exposure across devices and apps.
Recommendation — Prioritise rapid remediation for internet-facing and high-value systems.
NIST CSF 2.0PR.IP-12 — Vulnerability ManagementThe question asks for first-line actions that reduce common exposure across users and devices.
Recommendation — Establish a vulnerability handling process that drives timely patching and remediation.
NIST SP 800-53 Rev 5SI-2 — Flaw RemediationPatch flaws on systems and browsers is the primary technical exposure reduction step.
IA-2 — Identification and Authentication (Organizational Users)The answer recommends two-factor authentication for user access protection.
Recommendation — Remediate software flaws promptly on exposed endpoints and servers. Enforce multi-factor authentication for workforce access to critical systems.
OWASP ASVSV6 — AuthenticationTwo-factor authentication is a core user-facing control in the answer.
Recommendation — Require stronger authentication for accounts that protect sensitive services.

Practitioner Guidance

What to prioritise: Patch the systems that are internet-facing or heavily used first, then enforce 2FA on accounts that can expose email, cloud services, or administrative functions. Those two steps usually reduce more real-world exposure than adding more policy language.

What to verify: Confirm that patching is actually reaching browsers, endpoints, and IoT devices, not just servers. Also verify that users cannot bypass 2FA on critical services and that certificate warnings are not being normalised away by habit.

Common mistake: Treating awareness training as the primary control while leaving software stale. If the technical baseline is weak, user caution only limits damage, it does not remove the exposure.

Practitioner takeaway: The best first step is to shrink the attack surface people touch every day, because patching plus simple authentication habits removes far more risk than a purely advisory approach.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org